惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hacker News: Ask HN
Hacker News: Ask HN
O
OpenAI News
Cloudbric
Cloudbric
Attack and Defense Labs
Attack and Defense Labs
S
Secure Thoughts
J
Java Code Geeks
Help Net Security
Help Net Security
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
有赞技术团队
有赞技术团队
Security Archives - TechRepublic
Security Archives - TechRepublic
Hugging Face - Blog
Hugging Face - Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
GbyAI
GbyAI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
人人都是产品经理
人人都是产品经理
H
Help Net Security
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
W
WeLiveSecurity
Stack Overflow Blog
Stack Overflow Blog
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Jina AI
Jina AI
S
Security @ Cisco Blogs
月光博客
月光博客
Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
TaoSecurity Blog
TaoSecurity Blog
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
F
Fortinet All Blogs
S
Securelist
M
MIT News - Artificial intelligence
V
Vulnerabilities – Threatpost
小众软件
小众软件
T
Tenable Blog
Y
Y Combinator Blog
T
Threat Research - Cisco Blogs
博客园 - 叶小钗
N
News | PayPal Newsroom
A
About on SuperTechFans
C
CERT Recently Published Vulnerability Notes
Cyberwarzone
Cyberwarzone
L
Lohrmann on Cybersecurity

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Malware on Your Machine: A Developer's Complete Incident Response Guide
Red Masil · 2026-06-27 · via DEV Community

🛡️ Your Computer Got Infected — Now What? A Developer's Survival Guide to Malware Removal

A practical, no-BS walkthrough of detecting, containing, and eliminating malware — with real scenarios and the commands that actually work.


So it happened. Your machine is acting weird. Maybe Chrome is opening tabs you didn't ask for. Maybe your CPU is pegged at 95% doing... nothing. Maybe your antivirus just screamed at you. Whatever it is, that sinking feeling in your stomach is valid — but panic won't help. A methodical approach will.

This guide walks you through exactly what to do when your system is compromised, from initial triage to full recovery. I'll use real-world malware scenarios so you can match your situation to the right fix.


🚨 First: Know the Signs of Infection

Before we dive into removal, let's confirm we're actually dealing with malware and not a failing hard drive or a runaway Chrome extension.

Common infection symptoms:

  • Browser homepage changed without your input
  • Sluggish performance with abnormally high CPU/RAM/network usage
  • New toolbars, extensions, or programs you didn't install
  • Antivirus disabled or greyed out
  • Ransom notes appearing on your desktop (yes, really)
  • Your contacts receiving emails/DMs you never sent
  • System logs showing processes connecting to unknown IPs

If two or more of these apply to you — keep reading. You've got a problem.


🔬 Step 1: Don't Touch Anything Yet — Observe First

Scenario: You notice your system fan is running full blast at 2 AM while your computer is idle. You check Task Manager and see a process called svchost32.exe consuming 80% CPU.

🔴 Red flag: Legitimate Windows processes don't have numbers in their name like that. svchost.exe is real; svchost32.exe is almost certainly a cryptominer or trojan.

What to do:

Before you start killing processes or running scans, document what you're seeing. Take screenshots. Note the process names, PIDs, and any network connections.

On Windows (PowerShell, run as Admin):

# List all running processes with their full file paths
Get-Process | Select-Object Name, Id, Path | Sort-Object Name | Format-Table -AutoSize

# Check network connections and which process owns them
netstat -b -n -o

# See scheduled tasks (a favorite malware persistence trick)
Get-ScheduledTask | Where-Object {$_.State -ne "Disabled"} | Select-Object TaskName, TaskPath

On macOS/Linux (Terminal):

# Full process list with CPU usage
ps aux --sort=-%cpu | head -20

# Active network connections
sudo lsof -i -n -P | grep ESTABLISHED

# Cron jobs (persistence mechanism)
crontab -l
cat /etc/cron* 2>/dev/null


🔌 Step 2: Isolate the Machine — Cut the Network

Scenario: You ran the netstat command above and see your machine making outbound connections to an IP in a country you've never visited. The process is update_helper.exe — which you've never heard of.

This is classic C2 (Command & Control) communication — your machine is "phoning home" to a remote attacker who may be exfiltrating your data right now.

Act immediately:

  1. Disconnect from Wi-Fi — turn off the Wi-Fi adapter, don't just click disconnect
  2. Unplug the ethernet cable if wired
  3. Do NOT shut down yet — live memory may contain forensic evidence (encryption keys, attacker IPs, etc.) you'll want if this is a serious breach
  4. On Windows: Disable the NIC via Device Manager to be certain
# Disable a specific network adapter (replace "Ethernet" with your adapter name)
Disable-NetAdapter -Name "Ethernet" -Confirm:$false
Disable-NetAdapter -Name "Wi-Fi" -Confirm:$false


💾 Step 3: Back Up — But Be Careful What You Back Up

Scenario: You have a ransomware infection (you'll know because your files now have extensions like .locked, .encrypted, or .ryuk and there's a README_DECRYPT.txt on your desktop).

⚠️ Critical warning: Do NOT back up encrypted files as your only copy. Do NOT pay the ransom until you've checked for free decryptors (more on this later).

What to back up NOW (before any cleanup):

  • Uninfected documents, photos, and project files (check that they open correctly)
  • Browser bookmarks (export them manually)
  • SSH keys, .env files, API credentials — rotate these immediately after
  • Any database dumps or code repositories not already on GitHub/GitLab

What NOT to back up:

  • Executable files (.exe, .bat, .ps1, .sh) from your system — they may be infected
  • Your system restore points (may be compromised)
  • Browser extension data (could carry adware)

Use an external drive or a clean cloud upload — not another partition on the same disk.


🧹 Step 4: Boot into Safe Mode and Run Your Scans

Most malware is clever enough to defend itself while the OS is running normally — it hides its processes and blocks antivirus updates. Safe Mode loads the bare minimum, making the malware easier to kill.

Boot into Safe Mode with Networking:

  • Windows 10/11: Hold Shift → click Restart → Troubleshoot → Advanced Options → Startup Settings → Restart → Press F5
  • macOS: Hold Shift during startup (Apple Silicon: hold power button → select startup disk → hold Shift → Continue in Safe Mode)
  • Linux: At GRUB menu, select recovery mode or add single to kernel boot parameters

Now run these — in this order:

4a. Malwarebytes (Free Tier is sufficient)

Download from a clean device if needed. Malwarebytes is excellent at catching PUPs (Potentially Unwanted Programs), adware, trojans, and rootkits that traditional AV misses.

# After install, run a Threat Scan — it targets the most common infection locations:
# - Running processes
# - Startup entries  
# - Registry keys
# - File system hotspots (%AppData%, %Temp%, %ProgramData%)

4b. Windows Defender Offline Scan (Windows only)

This runs before Windows loads, catching bootkits and rootkits that hide at the OS level:

# Run this from PowerShell as Admin — it will schedule a pre-boot scan
Start-MpWDOScan

4c. RKill (Windows) — Kill Malicious Processes First

If your scanner keeps getting blocked or your AV won't open, use RKill from BleepingComputer to terminate known malicious processes before scanning:

# Run rkill.exe as Administrator
# It will generate a log of everything it killed — save this for later


🔍 Step 5: Manual Investigation — Go Deeper

Automated scanners miss things. Here's how developers should manually investigate.

Check Startup Entries

Scenario: Your browser keeps opening a casino website every time Windows starts, even after you've reset your homepage.

# Windows: Check all autorun locations
# Sysinternals Autoruns is the gold standard — download it from Microsoft
autoruns.exe  # Run as Admin, look for entries highlighted in red or yellow

# Via PowerShell:
Get-CimInstance -Class Win32_StartupCommand | Select-Object Name, Command, Location

# macOS — LaunchAgents are a common persistence location
ls -la ~/Library/LaunchAgents/
ls -la /Library/LaunchAgents/
ls -la /Library/LaunchDaemons/

# Linux — systemd services
systemctl list-units --type=service --state=running
ls /etc/systemd/system/

Inspect the Hosts File

Malware often hijacks your hosts file to redirect legitimate sites (like your bank) to phishing clones.

# Windows
notepad C:\Windows\System32\drivers\etc\hosts

# macOS/Linux
cat /etc/hosts

A clean hosts file should only have 127.0.0.1 localhost and ::1 localhost entries. Anything pointing to external IPs is suspicious.

Check Browser Extensions

Scenario: Your colleague clicked a "free PDF converter" Chrome extension and now everyone in the office is seeing ads injected into every website.

Chrome:  chrome://extensions/
Firefox: about:addons
Edge:    edge://extensions/

Remove anything you don't recognize or haven't intentionally installed. Even legitimate-looking extensions (e.g., "Grammar Checker Pro") can be malicious if they were silently installed.


🔐 Step 6: Ransomware — Specific Response Plan

Ransomware deserves its own section because the response is different.

Before paying anything:

  1. Identify the ransomware strain — upload the ransom note and a sample encrypted file to ID Ransomware
  2. Check for free decryptors at NoMoreRansom.org — law enforcement has cracked keys for dozens of strains including Ryuk, WannaCry variants, and Dharma
  3. Preserve the encrypted files — even if there's no decryptor today, one may exist in 6 months
  4. Report to authorities — in the US: IC3.gov, in the EU: your national CERT

If you have Volume Shadow Copies enabled (Windows):

# Check if shadow copies exist (ransomware often deletes these — check anyway)
vssadmin list shadows

# If they exist, you can restore individual files via:
# Right-click file → Properties → Previous Versions tab


🔄 Step 7: Remove and Remediate

Once you've identified the malware, it's time to remove it cleanly.

Registry Cleanup (Windows)

# Always back up the registry before editing
reg export HKLM\SOFTWARE backup_HKLM_SOFTWARE.reg

# Common malware persistence locations to inspect:
# HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
# HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
# HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

regedit  # Navigate manually and delete suspicious entries

Reset DNS Settings

Malware often changes your DNS to a rogue server that intercepts your traffic.

# Windows — reset DNS to automatic (DHCP)
netsh interface ip set dns "Ethernet" dhcp
netsh interface ip set dns "Wi-Fi" dhcp
ipconfig /flushdns

# Or set to a trusted public DNS
netsh interface ip set dns "Wi-Fi" static 1.1.1.1  # Cloudflare

# macOS
networksetup -setdnsservers Wi-Fi 1.1.1.1 8.8.8.8

# Linux
echo "nameserver 1.1.1.1" | sudo tee /etc/resolv.conf

Reset Browser Settings

Chrome: Settings → Reset and clean up → Restore settings to original defaults
Firefox: Help → More Troubleshooting Information → Refresh Firefox


🧱 Step 8: Rebuild Trust — Rotate Everything

Scenario: You found a keylogger on your machine. It's been running for 3 weeks.

Assume every password you typed is compromised. Assume every SSH session you opened is compromised. Act accordingly.

Immediate credential rotation checklist:

  • [ ] Change your email password (from a clean device first)
  • [ ] Enable 2FA on all accounts if not already on
  • [ ] Rotate all SSH keys: ssh-keygen -t ed25519 -C "post-incident-$(date +%Y%m%d)"
  • [ ] Revoke and regenerate all API keys (AWS, GitHub, Stripe, etc.)
  • [ ] Rotate database credentials and connection strings
  • [ ] Invalidate all active sessions (GitHub: Settings → Sessions → Revoke all)
  • [ ] Check your GitHub/GitLab for any unauthorized commits or OAuth apps
  • [ ] Notify your team if you share any services

✅ Step 9: Verify and Harden

You've cleaned up. Now let's make sure it doesn't happen again.

Verify the Cleanup

# Run a final Malwarebytes scan
# Run Windows Defender Full Scan
# Recheck netstat for unexpected connections
netstat -b -n | findstr ESTABLISHED

# Verify no new scheduled tasks appeared
Get-ScheduledTask | Where-Object {$_.Date -gt (Get-Date).AddDays(-7)}

Harden Going Forward

# Windows: Enable Controlled Folder Access (blocks ransomware from encrypting your files)
Set-MpPreference -EnableControlledFolderAccess Enabled

# Enable audit logging
auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable

# Linux: Install and configure fail2ban
sudo apt install fail2ban
sudo systemctl enable fail2ban

# Enable automatic security updates
sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrades

Universal hardening tips:

  • Use a password manager — stop reusing passwords
  • Keep your OS and apps updated (most infections exploit known, patched vulnerabilities)
  • Use a standard (non-admin) user account for daily use
  • Enable full-disk encryption: BitLocker (Windows), FileVault (macOS), LUKS (Linux)
  • Run a DNS-level blocker like Pi-hole or use NextDNS to block malicious domains before they load

🧨 Nuclear Option: When to Just Reinstall

Sometimes the malware is too deeply embedded — rootkits that survive OS reinstalls by hiding in the bootloader or firmware, for instance. Here's when to wipe and start fresh:

  • You found a bootkit or UEFI malware (rare, but it exists — tools like chkrootkit or rkhunter on Linux can detect these)
  • The infection is more than a few weeks old and you can't determine the full scope
  • You found a Remote Access Trojan (RAT) — assume total compromise
  • You're a high-value target (developer with production access, finance, healthcare) and you can't be 100% certain of a clean state
# If reinstalling Windows, use the "Remove everything" option with "Remove files and clean the drive"
# This does multiple overwrite passes — more thorough than a quick format

# On Linux, reinstall from a verified ISO (check the SHA256 hash)
sha256sum ubuntu-24.04-desktop-amd64.iso
# Compare against the hash published on ubuntu.com


📋 Quick Reference: Incident Response Checklist

DETECT
  [ ] Identify symptoms
  [ ] Document process names, PIDs, network connections

CONTAIN  
  [ ] Disconnect from network
  [ ] Do NOT shut down (preserve forensics)
  [ ] Photograph/screenshot everything

COLLECT
  [ ] Back up clean data to external drive
  [ ] Export browser bookmarks
  [ ] Note all installed software

ANALYZE
  [ ] Boot into Safe Mode
  [ ] Run Malwarebytes + Windows Defender Offline
  [ ] Check startup entries, hosts file, browser extensions
  [ ] Identify malware strain (ID Ransomware for ransomware)

REMOVE
  [ ] Delete malicious files/registry entries
  [ ] Remove suspicious extensions and software
  [ ] Reset DNS, reset browser settings

RECOVER
  [ ] Rotate all credentials from a clean device
  [ ] Revoke SSH keys, API keys, OAuth tokens
  [ ] Notify team if shared services were affected
  [ ] Report to authorities if data was exfiltrated

HARDEN
  [ ] Enable full-disk encryption
  [ ] Enable Controlled Folder Access / equivalent
  [ ] Set up automatic OS updates
  [ ] Deploy DNS-level filtering
  [ ] Review and tighten user privileges


🧠 Final Thoughts

Getting hit with malware is frustrating, but it's survivable if you stay calm and methodical. The biggest mistakes people make are:

  1. Panicking and shutting down immediately — you lose volatile forensic data
  2. Trusting a single scanner — layer your tools
  3. Stopping at "virus removed" — the malware got in somehow; find and close that door
  4. Skipping credential rotation — this is how one infection turns into an account takeover six weeks later

The developers who handle incidents best treat them like debugging sessions: gather data, form a hypothesis, test it, repeat. Your machine is just another system to troubleshoot — and you're good at troubleshooting.

Stay safe out there. 🔐


Have a specific malware scenario that isn't covered here? Drop it in the comments — I read everything.

Tags: #security #cybersecurity #tutorial #devops